Skip to content

Rank #3 of 6 in Hardware Security Keys

Token2 logo

Token2

Token2 Sàrl · commercial

11248/yr

Try itExperimental

See what an agent can do with Token2 before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).

$curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/token2/fido2-managerecorded session — replayed, not live
recorded 2026-09-15 · exit 0 · captured verbatim by our probe harness, secrets redacted

Verified integrations

No integration evidence found in our corpus for this product yet — that means none was found, never that it doesn’t integrate.

By theme — the product's score on each story themeBy theme

Agenticness — how well agents can access and operate the productAgenticnessevidence →

How well agents can access and operate the product

6.4/100

Automation depth — how much of the product can run unattendedAutomation depthevidence →

How much of the product can run unattended

36.0/100

Beyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fidoevidence →

What the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSH

16.5/100

Developer tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper toolingevidence →

Building with and managing the key — CLIs, SDKs, attestation

22.7/100

Ecosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compatevidence →

Where the key works — platforms, browsers, service compatibility catalogs

20.0/100

Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recoveryevidence →

Getting keys enrolled and surviving loss — setup flows, backup keys, lockout recovery

25.2/100

Firmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware opennessevidence →

What runs on the device — open-source firmware, update policy, vulnerability response

0.0/100

Fleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet managementevidence →

Keys at organization scale — bulk provisioning, delivery services, IdP policies

19.3/100

Form factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factorsevidence →

The physical lineup — NFC, USB-C/A, biometrics, certified and hardened models

8.0/100

Openness — open source, data portability, and self-hosting storiesOpennessevidence →

Open source, data portability, and self-hosting stories

21.0/100

Privacy posture — data-handling and privacy storiesPrivacy postureevidence →

Data-handling and privacy stories

15.0/100

Protocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverageevidence →

FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential management

61.8/100

Story verdicts — every judged story with its evidenceStory verdicts

?

Sorted by importance (agentic first) (high → low) · 54/54 stories · click a row’s chevron for the rationale and evidence

Drive the product through a documented public API G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3none0/10

Connect an agent via an official MCP server G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Delegate tasks to a built-in AI assistant inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Plug MCP servers into this product so it can use their tools G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness3n/auntestednone yet

Use an official CLI G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial5/10T

Run the product headlessly / in CI for automation G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2partial4/10T

Download a machine-readable API spec (OpenAPI or equivalent) G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Explore an interactive API reference with runnable examples G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Point an agent at llms.txt or agent-oriented docs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Rely on versioned APIs with a documented deprecation policy G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness2none0/10

Build against official SDKs G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2noneuntestednone yet

Get AI-generated insights and suggestions from my data inside the product G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Issue scoped/least-privilege API credentials for an agent G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Operate the product with natural-language commands G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Set up automations that run autonomously in the background G

Agentic features

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Subscribe to events via webhooks G

Agent access

ai-native userAgenticness — how well agents can access and operate the productAgenticness2n/auntestednone yet

Test against a sandbox environment without touching production data G

Api quality

ai-native userAgenticness — how well agents can access and operate the productAgenticness1n/auntestednone yet

The key stores discoverable FIDO2 credentials (resident keys / device-bound passkeys) so users can sign in to WebAuthn services without typing a username

Fido2

security engineerProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage3full8/10T

Configure and manage the key from an official CLI — enable applications, set PINs, manage slots, read device state — scriptably

Cli

developerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling3partial6/10T

Export all of my data in open formats and leave G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3partial5/10T

Provision keys across an organization at scale — pre-registration, bulk configuration, and lifecycle tracking of issued keys

Provisioning

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management3partial5/10T

The vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

Recovery

security engineerEnrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery3partial3/10C

Define rules that trigger actions automatically on events G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth3n/auntestednone yet

Prevent my data from being used to train AI models G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture3n/auntestednone yet

Self-host the core product G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness3noneuntestednone yet

The key supports on-device user verification — a FIDO2 PIN or built-in biometric — so a stolen key alone cannot authenticate

User verification

security engineerProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2full8/10T

List and delete the passkeys stored on my key and know its credential capacity before it fills up

Credential management

power userProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2partial7/10T

First-time setup is guided — clear instructions or a setup app walk me through registering the key with my accounts

Setup

power userEnrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryEnrollment recovery2partial6/10C

My SSH keys can be hardware-backed on the device — via FIDO2 sk-ssh keys, PIV, or OpenPGP — so server access requires a physical touch

Ssh

developerBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2partial6/10T

Perform bulk operations across many items at once G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2partial6/10T

Read the product's source under an open license G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial6/10T

The key works as a WebAuthn/U2F second factor across the major services I already use — Google, GitHub, Microsoft, password managers

Fido2

power userProtocol coverage — FIDO2/WebAuthn depth — resident-key passkeys, user verification, credential managementProtocol coverage2partial6/10C

An agent can read a key's state programmatically — serial, firmware version, enabled applications, stored credentials — to audit security posture across a fleet

Agent audit

ai-native userDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2partial5/10T

Control data retention and deletion G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2partial5/10C

The key acts as a PIV smart card for certificate-based login — workstation sign-in, VPN, and code signing with keys that never leave the device

Piv

it adminBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2partial5/10C

The key works across my operating systems and browsers, with a published compatibility catalog of supported services

Compatibility

power userEcosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat2partial5/10C

Do everything through the API that I can do in the UI G

ai-native userOpenness — open source, data portability, and self-hosting storiesOpenness2partial4/10T

Tap the key on my phone over NFC to authenticate in mobile browsers and apps

Nfc

power userForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2partial4/10C

The key integrates with my identity provider — Okta, Entra ID, Google Workspace — and I can enforce policies requiring hardware-key authentication

Idp

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2partial4/10T

An agent can drive key provisioning end to end — ordering, assignment, pre-registration — through documented enterprise APIs instead of a human-only console

Agent provisioning

ai-native userFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2partial3/10T

Verify device attestation at registration to enforce that only genuine, approved key models are enrolled

Attestation

security engineerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2partial3/10C

Official SDKs let me integrate the key into my own desktop and mobile apps

Sdks

developerDeveloper tooling — building with and managing the key — CLIs, SDKs, attestationDeveloper tooling2none0/10

The key covers legacy one-time-password schemes — TOTP/HOTP slots or challenge-response — for services that still lack WebAuthn

Otp

power userBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2none0/10

An enterprise delivery service ships keys directly to distributed employees, driven by an API or console rather than manual logistics

Delivery

it adminFleet management — keys at organization scale — bulk provisioning, delivery services, IdP policiesFleet management2noneuntestednone yet

Certified models exist for regulated environments — FIPS 140 validated or Common Criteria certified — with documented durability (water/crush resistance)

Certifications

it adminForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2noneuntestednone yet

Choose where my data is stored (region/residency) G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2n/auntestednone yet

Keep OpenPGP keys on the device and use them for git commit signing and encrypted email

Openpgp

developerBeyond fido — what the key does beyond FIDO — PIV smart card, OpenPGP, OTP slots, hardware-backed SSHBeyond fido2noneuntestednone yet

Opt out of telemetry and usage tracking G

ai-native userPrivacy posture — data-handling and privacy storiesPrivacy posture2noneuntestednone yet

Schedule recurring jobs or workflows G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth2n/auntestednone yet

The firmware is open source or independently audited, so I don't have to take the vendor's word for what runs on the device

Source

security engineerFirmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness2noneuntestednone yet

The lineup covers my ports and carry style — USB-C and USB-A models, keychain and low-profile nano form factors

Connectors

power userForm factors — the physical lineup — NFC, USB-C/A, biometrics, certified and hardened modelsForm factors2noneuntestednone yet

The vendor has a clear firmware update and vulnerability-response story — advisories, affected-model lookup, and how fixes reach devices

Updates

security engineerFirmware openness — what runs on the device — open-source firmware, update policy, vulnerability responseFirmware openness2noneuntestednone yet

Require a physical key touch as the human-approval step for sensitive automated or agent-initiated actions

Agent approval

ai-native userEcosystem compat — where the key works — platforms, browsers, service compatibility catalogsEcosystem compat1none0/10

Version, review, and roll back my automations G

ai-native userAutomation depth — how much of the product can run unattendedAutomation depth1n/auntestednone yet

Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 38 stories with headroom

What would move Token2’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.

  1. Agenticness — how well agents can access and operate the productDrive the product through a documented public API

    nonemoves agent-readyimpact 45

    Token2 is a hardware security key vendor; probes explicitly show no public API, no OpenAPI/Swagger spec, and no llms.txt (404s across all checked endpoints).

  2. Openness — open source, data portability, and self-hosting storiesSelf-host the core product

    nonemoves PA Scoreimpact 30

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".

  3. Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs

    nonemoves agent-readyimpact 30

    Direct probes show no llms.txt (404) and no markdown-accessible docs (404), and no OpenAPI/agent-oriented documentation exists; Token2 is a hardware security key vendor with no evidence of agent-discoverable docs.

  4. Agenticness — how well agents can access and operate the productBuild against official SDKs

    nonemoves agent-readyimpact 30

    The axis applies to this product kind (peer products hold positive or none verdicts on this story), so lack of evidence for an applicable capability is "none", never "na".

  5. Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples

    nonemoves API qualityimpact 30

    Token2 is a hardware security key vendor with no evidence of an API reference at all — the probes explicitly show no OpenAPI/swagger spec exists (404s across all candidate paths) and no llms.txt or docs.md exposure.

  6. Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)

    nonemoves API qualityimpact 30

    Token2 is a hardware security key vendor with desktop/browser tools and a CLI, but there is no evidence of a machine-readable API spec; explicit probes for OpenAPI/Swagger endpoints and llms.txt all returned 404.

  7. Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy

    nonemoves API qualityimpact 30

    Token2 is a hardware security key vendor with desktop/CLI tools for FIDO2/PIV management; there is no evidence of any versioned public API, and probes confirm no OpenAPI/Swagger spec exists (404s across all candidate paths).

  8. Enrollment recovery — getting keys enrolled and surviving loss — setup flows, backup keys, lockout recoveryThe vendor documents a credible lockout-recovery strategy — registering a backup key, and what is and is not recoverable if a key is lost

    partialq3/10moves PA Scoreimpact 21

    Missing: detailed recovery/lockout policy content, explicit statement of non-recoverable data (e.g., resident key private keys), and any independent corroboration of the backup-key workflow.

Showing the top 8 of 38 — every none/partial verdict in the story verdicts table is headroom.

Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.

Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map5 surfaces · 23 covered stories

Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.

GitHub README20 stories

Site docs19 stories

Probe proofs — replayable recordings from the probe harnessProbe proofs

Replayable recordings from our probe harness — see the Prove-It protocol to submit one.

$curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/token2/fido2-managereproduced
$ curl -sL -o /dev/null -w "%{http_code} %{url_effective}" https://github.com/[redacted]2/fido2-manage
200 https://github.com/[redacted]2/fido2-manage

Business model

hardware-purchase

Hardware purchase, cheapest certified keys in the arena — Pico RP2350 key $8.08, KeyTen NFC $20.77, PIN+ Release3.3 with PIV and TOTP $25.39. Swiss vendor.

pricing ↗

Score trend

How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.

PA Scoretracked since Sep 15 '26 — no movement recorded yet
Agent-readytracked since Sep 15 '26 — no movement recorded yet

Try Experimental

Run it in the microterminal →

Recorded agent sessions — and a live MCP handshake where the vendor ships one.

Flag

⚑ Flag a verdict

Think a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.

Badge

Embed this product's score badge →

Hotlinked SVG — always shows the live current score.

For agents

Data